Should E-Mail Addresses Be Considered Private Data?
A database of e-mail addresses and other contact information stolen from business software provider Salesforce.com is being used in an ongoing series of targeted e-mail attacks against customers of several Salesforce.com business clients, including SunTrust and Automatic Data Processing Inc. (ADP), one of the nation's largest payroll and tax services providers.
Security Fix learned of the data breach through a SunTrust customer who received a curious e-mail in mid-September; the message was sent to a custom e-mail address the guy had created for use exclusively with SunTrust. The message, which was addressed to the recipient by name and mentioned his company, urged him to download a PDF document to help resolve an identity theft complaint he had supposedly filed with SunTrust.
The recipient, who asked to remain anonymous to avoid any further risk of identity theft, said earlier this week that he received an e-mail from SunTrust that said a "third-party database used by a number of financial service providers, including SunTrust, was improperly accessed" [emphasis added.]
